Implementing Identity-Centric Zero Trust with IAM Policies and Roles
摘要
Access control management is fundamental to any secure system, including those built on AWS. In this chapter, we will discuss the high-level principles of access control in relation to AWS services and then dive into the practical aspects of managing access control in AWS. This starts with the AWS Identity and Access Management (IAM) service, which is used to manage access to AWS resources and services. IAM is the enabling service for both access management policies and secure access to AWS resources. Following IAM, we move on to AWS Cognito, a service designed to manage access to applications securely, allowing you to set up diverse and robust access schemes for the users of your applications.